<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: mandiant]]></title>
    <link>http://securityratty.com/tag/mandiant</link>
    <description></description>
    <pubDate>Wed, 26 Dec 2007 08:54:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Darn Good Idea ... If Done Well]]></title>
      <link>http://securityratty.com/article/2c9abb3c29fb2916c057241cbd14d900</link>
      <guid>http://securityratty.com/article/2c9abb3c29fb2916c057241cbd14d900</guid>
      <description><![CDATA[A free, downloadable, log management and compliance product that provides organizations with visibility across their networks, data centers, and infrastructures?&quot; ( here

Somebody, somewhere is...]]></description>
      <content:encoded><![CDATA["A free, downloadable, log management and compliance product that provides organizations with visibility across their networks, data centers, and infrastructures?" (<a href="http://www.q1labs.com/pr.php?id=711">here</a>)<br /><br />Somebody, somewhere is thinking ...<br /><br />In any case, "free is in" :-)  Look at all the announcements (<a href="http://download.netwitness.com/download.php?UI=">NetWitness</a>, <a href="http://www.mandiant.com/software/firstresponse.htm">Mandiant</a>, <a href="http://www.q1labs.com/pr.php?id=711">this</a>) as well as "<a href="http://www.splunk.com/download">the original free.</a>"<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=4pcxN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=4pcxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=N1ZJN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=N1ZJN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=M4F4N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=M4F4N" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/458898787" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 11:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/original free">original free</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/data centers">data centers</category>
      <category domain="http://securityratty.com/tag/compliance product">compliance product</category>
      <category domain="http://securityratty.com/tag/mandiant">mandiant</category>
      <category domain="http://securityratty.com/tag/netwitness">netwitness</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/458898787/darn-good-idea-if-done-well.html">Darn Good Idea ... If Done Well</source>
    </item>
    <item>
      <title><![CDATA[Malware analysis tools]]></title>
      <link>http://securityratty.com/article/fb65a2d4609cbcefc5bdbbb91ee3d8c8</link>
      <guid>http://securityratty.com/article/fb65a2d4609cbcefc5bdbbb91ee3d8c8</guid>
      <description><![CDATA[I've been asked to share the tools I use for malware analysis, in particular API details
The Malcode Analysis Software Tools from iDefense Labs are extremely useful. toolsmith featured the suite in...]]></description>
      <content:encoded><![CDATA[I've been asked to share the tools I use for malware analysis, in particular API details. <br />The <a href="http://labs.idefense.com/software/malcode.php">Malcode Analysis Software Tools</a> from <a href="http://labs.idefense.com/">iDefense Labs</a> are extremely useful. <span style="font-style:italic;">toolsmith</span> featured the suite in the <a href="http://holisticinfosec.org/toolsmith/docs/july2007.pdf">July 2007</a> column.<br /><a href="http://labs.idefense.com/files/labs/releases/previews/SysAnalyzer/ApiLogger.html">API-Logger</a> can be used as a standalone tool or you can run the .exe through SysAnalyzer which includes API-Logger output.<br />Other important pieces in my sandbox included <a href="http://www.vmware.com/products/server/">VMWare Server</a> (Linux host, Windows VMs), <a href="http://www.heaventools.com/overview.htm">PE Explorer</a>, <a href="http://code.google.com/p/rapier/">RAPIER 3.2</a>, <a href="http://www.wireshark.org/">Wireshark</a>, <a href="http://mandiant.com/mrc">Mandiant Red Curtain (MRC)</a>, and the <a href="http://technet.microsoft.com/en-us/sysinternals/default.aspx">Systinternals</a> tools.<br />Check the <a href="http://holisticinfosec.org/content/view/12/26/">toolsmith</a> page for articles on <a href="http://holisticinfosec.org/toolsmith/docs/november2006.pdf">Wireshark</a>, <a href="http://holisticinfosec.org/toolsmith/docs/december2007.pdf">MRC</a>,  and <a href="http://holisticinfosec.org/toolsmith/docs/february2007.pdf">RAPIER</a> use as well.<br />Required reading from the "The Godfather of RE", <a href="http://www.zeltser.com/">Lenny Zeltser</a>, includes his <a href="http://www.zeltser.com/reverse-malware-paper/">Reverse Engineering Malware</a> paper. <br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html&title=Malware%20analysis%20tools" title="Malware analysis tools del.icio.us"><img src="http://holisticinfosec.org/images/delicious.png" class="socialbkmark" border=0 alt="Malware analysis tools at del.icio.us"></a><a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html" title="Malware analysis tools "> <img src="http://digg.com/img/badges/16x16-digg-guy.gif" border=0 class="socialbkmark" alt="Digg Malware analysis tools "></a>]]></content:encoded>
      <pubDate>Wed, 26 Dec 2007 08:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/api-logger">api-logger</category>
      <category domain="http://securityratty.com/tag/includes api-logger output">includes api-logger output</category>
      <category domain="http://securityratty.com/tag/includes">includes</category>
      <category domain="http://securityratty.com/tag/malware analysis">malware analysis</category>
      <category domain="http://securityratty.com/tag/toolsmith page">toolsmith page</category>
      <category domain="http://securityratty.com/tag/toolsmith">toolsmith</category>
      <category domain="http://securityratty.com/tag/mandiant red curtain">mandiant red curtain</category>
      <category domain="http://securityratty.com/tag/systinternals tools">systinternals tools</category>
      <source url="http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html">Malware analysis tools</source>
    </item>
  </channel>
</rss>
